HOSIAS (Business Experience Together) — Privacy Policy
Version: Launch draft — current product model
Draft date: 7 September 2026
Effective date: [LAUNCH EFFECTIVE DATE]
Status: DRAFT — do not publish or activate for external
users until the HOSIAS contact email is inserted and the launch legal check
is completed.
1. Who controls your personal data
The controller of personal data processed through HOSIAS (Business Experience Together) is:
Magdalena Ciombor
Spokojna 2C
32-010 Wilków
Poland
Email: [HOSIAS CONTACT EMAIL]
This Privacy Policy explains how HOSIAS collects, uses, shares, stores and protects personal data in connection with the HOSIAS website, application and related services.
2. Who HOSIAS is for
HOSIAS is intended only for people aged 18 or over who have real business decision-making experience: people who currently or previously owned/founded a real business or held a senior executive role with real responsibility for business decisions and outcomes.
HOSIAS is not intended for children.
3. The main privacy principles used by HOSIAS
HOSIAS is designed around the following principles:
- account-gated knowledge rather than a public member database;
- minimum necessary use of personal data;
- separation between information HOSIAS needs to know and information other members are allowed to see;
- private-by-default business questions;
- private Notes that are not used by HOSIAS Intelligence;
- no advertising profiles, no cross-site advertising tracking and no sale of personal data;
- human business experience as the source of Experience records, with AI used as supporting infrastructure;
- access and moderation controls applied server-side where appropriate;
- role-based, need-to-know internal access for verification, support, moderation and operations, with Private Notes excluded from normal Owner/Staff access;
- separation between private Decision history and Experiences explicitly contributed to collective HOSIAS knowledge.
4. Personal data HOSIAS may collect
Depending on how you use HOSIAS, we may process the following categories of data.
4.1 Account and identity data
- email address;
- authentication identifiers and account status;
- display name, if provided;
- email-confirmation and login/security information;
- Terms and Privacy Policy version accepted and acceptance time;
- signup country and other account metadata necessary to operate the Service;
- preferred display/content language, language preferences and language-detection metadata where used to provide multilingual functions.
HOSIAS does not need your password in readable form. Authentication credentials are handled through the authentication infrastructure used by the Service.
4.2 Verification data
To determine whether you are eligible for HOSIAS, we may process:
- business/company name;
- country;
- business registration number or company ID;
- role(s), such as Owner, Founder, Co-founder, CEO, Managing Director or another executive role;
- whether the role is current or former;
- period of work/association where relevant;
- associations with multiple current or former businesses where relevant;
- publicly available business/professional information used to verify your role or business;
- limited additional evidence if public/business information is insufficient to verify eligibility.
Document uploads are not the default verification method. If additional evidence is requested, HOSIAS will seek only the minimum reasonably necessary and will not keep it longer than required for verification, security and applicable legal obligations.
4.3 Profile and business-context data
Business context can include:
- industry;
- role;
- country;
- company/team size: Solo / 1 person; 2–10; 11–50; 51–200; 201–500; 500+;
- company stage: Early stage / startup; Growth; Established / mature; Exit / sold; Closed / failed;
- optional full name, company name, profile photo, links and other details you choose to reveal;
- your visibility/privacy settings;
- historical Business Snapshots or context entries used to preserve the business context that applied when a Decision or Experience occurred.
Industry, role, country, company size and company stage are contextual fields that HOSIAS may show when your Experience/profile is displayed to another eligible member in a product context permitted by HOSIAS. Identifying information such as your full name, company name, photo and links is optional and controlled by your visibility choices, except where HOSIAS must retain information internally for verification, security or legal purposes.
A profile photo is optional and is not required for verification.
4.4 Business questions, Decisions and problems
HOSIAS processes the business questions/problems and Decision records you submit, their context, status and related actions. Questions and Decisions are private by default and are processed to provide Ask HOSIAS and Decision Space, retrieve relevant Experience, perform matching, preserve evidence snapshots of what was known at the relevant time, record actions/outcomes/later updates and operate related workflows.
A private Question, Decision or business-journey record does not automatically become a contributed Experience. If you explicitly choose to contribute material from a private record, HOSIAS creates or uses a separate submitted object for the permitted HOSIAS function.
4.5 Experiences and business journey data
HOSIAS may process Experience records and related data you submit about real business situations, decisions, actions and outcomes, including:
- the content of the Experience;
- contextual business information;
- versions and edits;
- withdrawal status;
- outcome follow-ups;
- relationships between an Experience and a question, Decision, match or evidence output where necessary to provide HOSIAS;
- stable Experience record identifiers, immutable version history and provenance needed to identify which source version supported a historical Evidence output;
- status needed to stop future retrieval/matching after withdrawal and to invalidate search/index derivatives;
- original-language metadata and derived machine translations where multilingual retrieval or display is enabled.
Do not submit third-party personal data, trade secrets, NDA-protected information or other confidential information unless you have a lawful right to provide it.
4.6 Threads, conversations and shared interaction history
When HOSIAS creates a problem-bound invitation, thread or conversation, we process the messages, participants, timestamps, invitation/participation status, reports/moderation information and context necessary to provide and protect that conversation. We may also process the original language of a message and create derived machine translations so participants who use different languages can read the conversation in a preferred language. Where specific content is reported, HOSIAS may preserve a limited restricted copy or evidence context where reasonably necessary to investigate the report, protect members, comply with law or establish/defend claims, even if the visible message is later edited or removed. Such moderation evidence is not added to the Experience Graph or used for normal matching.
HOSIAS is not a general open messaging network. Conversations are tied to permitted HOSIAS contexts, such as qualified matches or relevant business problems.
4.7 Private Notes
Private Notes are treated as a separate private workspace.
HOSIAS Intelligence does not use Private Notes for Ask HOSIAS, matching, indexing, embeddings or model training. They are not shown to other members. HOSIAS's normal Owner, Staff and administrative product interfaces do not provide routine access to their contents, and Private Notes are excluded from HOSIAS Intelligence, matching and Owner analytics.
If you choose Use in HOSIAS, a separate submitted copy is created for use in HOSIAS. The original private Note remains private.
4.8 Notifications and support
We may process notification preferences and records needed to send operational messages, including:
- account confirmation and password reset;
- verification status;
- account/security notices;
- new qualified match notifications;
- notifications that you may have relevant experience;
- problem-bound message/invitation notifications;
- outcome follow-ups;
- support requests and related correspondence.
Creating a HOSIAS account or subscription does not itself constitute consent to marketing or newsletter email.
4.9 Technical, security and service-use data
We may process data such as:
- IP address and limited network/security information;
- browser/device and request information;
- authentication/session events;
- timestamps;
- error and security logs;
- server-side product events such as account creation, login, Experience submission, question creation, match generation and conversation creation;
- consent records and preference versions;
- internal access/audit events needed to record authorized staff actions;
- product-activity events and active-time signals used to understand service operation without treating an idle open tab as active use.
We use this information to operate, secure, troubleshoot and understand the functioning of HOSIAS. HOSIAS does not intentionally collect keystroke logs, the content of text you type but do not submit, or the content of Private Notes for product analytics.
5. Where personal data comes from
We obtain personal data primarily:
- directly from you when you register, complete verification, create a profile or use HOSIAS;
- automatically from your use of the Service, where necessary for security, authentication, technical operation or permitted analytics;
- from public business registers and publicly available business/professional sources when reasonably necessary to verify your business or executive role;
- from other members where they interact with you in a permitted HOSIAS thread or report content involving you.
6. Why HOSIAS processes personal data and the legal bases
HOSIAS processes personal data only where a valid legal basis applies.
6.1 Providing the HOSIAS service — performance of a contract / steps requested before a contract
We process account, authentication, verification, profile, business context, Questions, Decisions, Experiences, matching, conversations, private Notes, notifications and support data where necessary to provide the Service you request, manage your account and enforce the access model.
6.2 Verification, platform integrity, safety and fraud prevention — legitimate interests
We may process verification information, public business information, security logs, reports and related data where necessary for legitimate interests such as:
- ensuring that HOSIAS remains limited to eligible business decision-makers;
- preventing fraud, impersonation, abuse and manipulation;
- protecting members and the integrity/security of the Service;
- moderating unlawful, harmful or confidential content;
- maintaining limited role-based staff access, security/audit records and service integrity;
- establishing, exercising or defending legal claims.
Where processing relies on legitimate interests, HOSIAS considers the necessity of the processing and the rights and interests of the people affected.
6.3 Legal obligations
We may process or retain data where necessary to comply with obligations imposed by applicable law or binding requests from competent authorities.
6.4 Optional analytics — consent where required
Non-essential browser-side product analytics, cookies or equivalent storage will be used only where permitted by law and, where consent is required, only after valid consent. Consent can be withdrawn or preferences changed later.
Strictly necessary authentication, session, security and member-preference technologies may be used without optional analytics consent where the law permits because they are necessary to provide the service requested by the user.
7. AI and automated processing
HOSIAS may use AI and other automated tools to:
- structure Experience records;
- identify and normalize business context;
- retrieve and compare relevant experience;
- assist matching;
- create Evidence/Intelligence outputs;
- support service functions where appropriate;
- detect language and create machine translations for cross-language retrieval, Intelligence presentation and permitted conversations.
AI is not permitted to invent source facts or present a member-reported statement as independently verified fact.
HOSIAS minimizes the data sent to external AI infrastructure. Before real user content is processed through an external AI provider, HOSIAS will use provider terms/configurations intended not to permit that provider to use HOSIAS user content to train its own models.
AI does not make authorization decisions for HOSIAS. AI may assist retrieval, Business-context structuring, matching, moderation triage or operational workflows, but verification, staff/member access and other high-impact account actions are not based solely on an external AI provider. Matching and AI-assisted processing may involve profiling in the ordinary technical sense of comparing business context, but HOSIAS does not use such processing to make decisions that produce legal effects or similarly significant effects about you without appropriate safeguards and a lawful basis.
Language detection and machine translation
HOSIAS may detect the language of content you submit and create machine-translated versions for permitted product functions. The original user-authored content remains the source record; translations are derived operational/presentation data associated with the relevant source version or message.
Translation may be performed by an external translation provider or AI infrastructure under an appropriate provider arrangement. HOSIAS intends to send only the text and minimum context necessary for the translation task rather than unrelated profile, Decision, thread or account data. The actual provider(s) used with real user data must be included in the launch subprocessor/provider inventory.
Translation artifacts follow the access, withdrawal, deletion and retention lifecycle of their source. If a source Experience is withdrawn, edited into a new version, deleted or otherwise becomes unavailable for a purpose, related active translation/search derivatives will be invalidated or removed as appropriate.
Private Notes are not sent to external translation/AI infrastructure
merely because HOSIAS supports multiple languages. If you explicitly choose
Use in HOSIAS, the separate submitted copy may then be
processed according to the rules for that submitted object.
8. Who can see your data inside HOSIAS
HOSIAS distinguishes between information it needs internally and information visible to another member.
There is no public member directory and no public access to HOSIAS's collective Experience Graph.
A person without an account cannot access member-layer content. A registered user whose verification is pending or rejected does not receive full access to Ask HOSIAS, Experiences, member content or threads.
Verified and accepted members may see only the information made available to them through permitted HOSIAS functions and contexts. Access to other people occurs through specific product contexts, especially problem-bound threads and qualified matches, not through unrestricted browsing of a community.
Where relevant to a permitted match, Experience or member context, HOSIAS may display the required business-context fields: industry, role, country, company size and company stage. Identifying information is shown according to your visibility choices and the applicable HOSIAS permissions.
Internal access by HOSIAS Owner and authorized staff
HOSIAS may allow the Owner and specifically authorized staff or contractors to access limited personal data where necessary for verification, support, Trust & Safety, security, billing/operations (when applicable) or other legitimate service administration. Internal access is intended to be role-based, scoped to the task, server-authorized and auditable.
For example, a Verification Agent should receive only the data needed to review eligibility; Support should receive the minimum account and diagnostic context needed to resolve a support case; and a moderator should receive reported content plus only the context reasonably needed to review the report. A staff role does not automatically provide unrestricted access to all member content.
Private Notes are excluded from normal Owner/Staff product access and from HOSIAS Intelligence. Aggregate Owner metrics do not create an independent right for staff to inspect the underlying private content.
9. Sharing with service providers and other recipients
HOSIAS may disclose personal data only where necessary and subject to appropriate legal/contractual safeguards to categories of recipients such as:
- cloud hosting, database, authentication and storage providers;
- web hosting/CDN providers;
- transactional email providers;
- AI infrastructure providers, when activated under appropriate no-training arrangements for HOSIAS user content;
- machine-translation providers, where activated to provide cross-language retrieval, display or conversation functions;
- security, monitoring and technical-support providers;
- professional advisers where necessary for legal, accounting, security or compliance purposes;
- competent public authorities where disclosure is legally required;
- other verified HOSIAS members, but only to the extent permitted by the product access model and your applicable visibility settings.
HOSIAS does not sell personal data. HOSIAS does not provide data to advertising networks and does not use production member data for advertising profiles.
Before external launch, HOSIAS will maintain an up-to-date record of the processors/subprocessors actually used for the launch configuration.
10. International data transfers
Some service providers may process data outside Poland or the European Economic Area.
Where a transfer of personal data outside the EEA requires a transfer mechanism, HOSIAS will use an applicable safeguard, such as an adequacy decision or Standard Contractual Clauses, together with supplementary measures where required.
11. Retention
HOSIAS does not intend to keep identifiable personal data indefinitely.
11.1 Active accounts
Account and service data are generally kept while your account exists and for as long as needed to provide HOSIAS.
11.2 Verification data
Verification information is kept only as long as necessary to establish and maintain eligibility, protect the Service and meet applicable legal/security requirements. Information connected with a rejected verification is not intended to be kept indefinitely and will be retained only as long as needed for re-verification, security and legitimate/legal requirements.
Additional verification evidence requested because standard verification was insufficient will be retained only for the minimum period reasonably necessary for that purpose and related security/legal needs.
11.3 Experiences
You may edit or withdraw an Experience. Material edits create a new source version rather than silently overwriting the source version previously relied on. Withdrawal stops future retrieval and new matching and HOSIAS will invalidate active search/index derivatives used to surface the withdrawn Experience. Historical Decision/evidence records may retain limited provenance showing that a specific source version existed or was used at that time, but withdrawn source content is not made newly accessible through that historical reference. If an Experience has contributed to genuinely anonymized Intelligence that can no longer be linked to you or a specific company, that anonymized output may remain.
Derived machine translations associated with an Experience or Message are not independent source records and are retained only while needed for the relevant product purpose/cache, subject to the source object's access, withdrawal/deletion and applicable legal/security requirements.
11.4 Account deletion
When you permanently delete your account or your deletion request is completed:
- personal account data will be deleted or anonymized without undue delay, subject to necessary legal/security retention;
- your Experience may remain only after effective anonymization so it cannot be linked to you or a specific company; otherwise it will be removed;
- your Private Notes and other private account workspace data will no longer remain available as part of your account;
- active search indexes, embeddings/caches, machine-translation artifacts or other derived operational copies used to surface deleted private data will be deleted or invalidated through the deletion workflow;
- messages you previously sent in shared problem-bound threads may remain where necessary to preserve the continuity of the conversation for other participants, but your identity may be replaced by a neutral label such as Deleted member;
- content that must be removed for legal, privacy or safety reasons will be removed or appropriately anonymized.
Deleted data may remain temporarily in protected backups until overwritten through the normal backup-rotation process. Such backup copies are not intended to be restored for ordinary product use after a valid deletion request.
11.5 Security, legal and consent records
Security logs, evidence of acceptance/consent, staff-access audit records, moderation records (including limited restricted evidence connected to a specific report) and limited records needed for legal claims may be retained for the period reasonably necessary for security, compliance, dispute resolution and applicable limitation/legal retention periods. HOSIAS does not use such restricted records as ordinary matching or Experience-Graph content.
12. Cookies, local storage and similar technologies
HOSIAS separates browser technologies into these categories:
- Strictly necessary — authentication/session/security and explicit member preferences required to provide the Service.
- Product analytics — optional browser-side product measurement, used only where permitted and with consent where required.
- Marketing — not part of the production launch scope.
HOSIAS does not use advertising trackers or cross-site marketing profiles.
Where optional consent is required, the interface will allow users to reject non-essential technologies, accept them or manage preferences, and later change the decision. Non-essential trackers will not be intentionally loaded before required consent.
Core server-side operational events do not depend on advertising cookies.
13. Operational emails
HOSIAS may send emails necessary to provide the Service, including account confirmation, password reset, verification status, account security, important Terms/Privacy updates, qualified-match notifications and relevant problem-bound notifications. Certain security/account communications may be mandatory where necessary to provide or protect the Service; other value notifications may be configurable where the product permits.
These are service communications, not marketing.
HOSIAS does not operate a newsletter or marketing-email program during the Service. If marketing is used, it will require a separate lawful basis and, where required, separate voluntary consent before launch.
14. Content moderation and reports
HOSIAS processes reports and moderation information where necessary to protect members, enforce the Terms, comply with applicable law and address allegedly illegal content.
A report should relate to specific content or a specific event. Available reporting categories may include bullying/harassment, hate speech, threats, personal attack, spam/manipulation, sharing private/confidential information and other concerns.
HOSIAS may use human review and limited automated assistance for moderation. Moderation may result in a request for correction, restriction, hiding, withdrawal or removal of content, or account action under the Terms. Where applicable law requires notice-and-action procedures, HOSIAS will process sufficiently actionable notices diligently and objectively, confirm receipt and communicate the decision/redress information as required. Where content or account access is restricted for illegality or Terms violations, HOSIAS will provide the affected user with an appropriate statement of reasons where required by law.
15. Your data-protection rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- obtain confirmation whether HOSIAS processes your personal data and access a copy;
- correct inaccurate or incomplete data;
- request erasure of data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain data in a portable format where the right to portability applies;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with a competent data-protection supervisory authority.
To exercise a right, contact [HOSIAS CONTACT EMAIL]. HOSIAS may need to verify your identity before acting on a request.
Because HOSIAS is established in Poland, you may lodge a complaint with the Polish supervisory authority:
President of the Personal Data Protection Office (Prezes
UODO)
Personal Data Protection Office (Urząd Ochrony Danych Osobowych)
ul. Stanisława Moniuszki 1A
00-014 Warsaw
Poland
You may also have the right to complain to another competent supervisory authority, for example in the EU/EEA country of your habitual residence, place of work or the alleged infringement.
16. Your responsibilities when submitting information about other people
HOSIAS is designed for business experience, not for collecting unnecessary personal data about third parties.
If you include information about another person in an Experience, message or other content, you are responsible for ensuring that you have a lawful right to disclose it. Do not provide third-party personal data, confidential information, trade secrets or NDA-protected information where you are not authorized to do so.
HOSIAS may remove, anonymize or restrict content where necessary to protect privacy, confidentiality or legal rights.
17. Security
HOSIAS applies technical and organizational measures intended to protect personal data and the account-gated Service, including server-side authentication/authorization, restricted access, secure transport and security controls appropriate to the stage and nature of the Service.
No online system can be guaranteed to be completely secure. If you suspect unauthorized account access or a security issue involving your data, contact HOSIAS promptly.
18. Changes to this Privacy Policy
HOSIAS may update this Privacy Policy when the Service, legal requirements, processors or data practices change.
Material changes will be communicated appropriately. Where a new processing activity requires consent or another specific legal step, HOSIAS will complete that step before relying on the new processing basis.
If the legal operator/controller changes in the future, including a transfer of HOSIAS to a company before paid services are introduced, HOSIAS will update this Policy and inform affected users before the change takes effect as required by law.
19. Contact
Questions about privacy, data requests and privacy complaints should be sent to:
Magdalena Ciombor / HOSIAS
Spokojna 2C
32-010 Wilków
Poland
Email: [HOSIAS CONTACT EMAIL]
Launch blockers:
- replace [HOSIAS CONTACT EMAIL];
- set the effective date and freeze Version 1.0 before the first external account accepts it;
- confirm the actual launch subprocessor list, including the transactional email provider and any AI provider used for real user content;
- confirm the live cookie/local-storage inventory and ensure optional analytics are blocked until consent where required.